Did you know that there is a way to connect one of your Security Gateways to a switch mirror (span) port on a switch to run security inspection of the traffic without interfering?
This type of deployment is called Monitor Mode.
Monitor Mode on Check Point Security Gateway interface is usually configured to monitor and analyze network traffic without affecting the production environment.
You can use mirror ports in the following scenarios:
- As a permanent part of your deployment, to monitor the use of applications in your organization.
- As an evaluation tool for the capabilities of the Application Control and Threat Prevention blades before you decide to purchase them.
Benefits of a mirror port include:
- There is no risk to your production environment.
- It requires minimal set-up configuration.
- It does not require TAP equipment, which is much more expensive.
Read the following article for more information: Monitor Mode on Gaia OS and SecurePlatform OS.